Split the job. The people who know your organization, staff or volunteers, should edit the website: news, events, pages, notices to members. Someone accountable, and paid to be, should manage it: software updates, security, backups, hosting and fixes. Whoever does either, the organization itself should own the domain, the hosting account and an administrator login, so the website does not leave when a person does.
That is the arrangement we recommend to associations, leagues, clubs and professional firms, including the ones that never hire us. The rest of this article explains why, and how to choose who takes the technical half.
What does “managing a website” actually involve?
Two different jobs get called “managing the website”, and they suit different people.
| Editing (the content) | Managing (the technical side) |
|---|---|
| Writing and updating pages, news and events | Applying WordPress, theme and plugin updates |
| Posting schedules, minutes and renewal notices | Watching for downtime and security problems |
| Swapping photos, fixing a typo | Keeping backups, and checking they actually restore |
| Deciding what the site should say | Renewing the domain, running hosting, fixing what breaks |
Editing needs someone who knows the organization. Managing needs someone who knows the software and is answerable when it fails. Most trouble starts when one person is quietly expected to do both, or when the technical job belongs to nobody at all.
The technical job is not optional. WordPress’s own security guidance is blunt: older versions “are not maintained with security updates” (Hardening WordPress). The Canadian Centre for Cyber Security treats patching, backups you have tested, and tight control of administrator accounts as part of the minimum for small and medium organizations, not as extras (Baseline cyber security controls).
Can a volunteer manage the website?
For editing, often yes. For the technical side, it is the riskiest option, and the reason is turnover rather than skill.
A familiar story: a board member builds the site, the logins sit in their personal email, and the domain renews on their credit card. Two years later they step down, and nobody can log in or say when the domain expires. The Cyber Centre’s baseline asks organizations to remove access when people no longer need it (control BC.12.3). That is hard to do when nobody knows what access exists.
If a volunteer does take the technical side, make it survivable:
- Write down where the site is hosted, who has administrator access, when the domain renews and where the backups are.
- Give a second person administrator access, in their own name, not a shared login.
- Review the list every year when the board changes.
Should a staff member do it?
If you have staff, the content side usually belongs with them. A communications coordinator is often the best editor you could ask for.
The technical side is a different job. Updates land on nobody’s calendar, and when something breaks in renewal week it becomes that person’s week. A staff member can manage the site well when three things are true: the site is fairly simple, they have the skills, and someone covers for them when they are away.
When does it make sense to hire someone?
Bring in outside help for the technical side when any of these apply:
- The site takes money or personal information. Registrations, renewals, payments or a member area raise the cost of getting security wrong.
- Downtime would hurt. Renewal season, a tournament weekend, the week before an AGM.
- Nobody inside can answer basic questions. Which plugins are installed, when they were last updated, where the backups are.
- You have accessibility obligations to keep meeting. A site that was accessible at launch can drift as content and plugins change.
There are three common arrangements:
- A freelancer, by the hour. Flexible, and fine for occasional jobs. The risk is that nobody is watching between calls.
- Managed hosting from your web host. The host looks after the server. Usually not your plugins, your theme or your content, so check exactly what is covered.
- A monthly care plan from a web company. Updates, monitoring, backups and fixes as a standing arrangement, sometimes with small improvements included.
Whichever you choose, look for named people, what is included in writing, how quickly they respond when something breaks, and confirmation that you keep ownership of everything.
Disclosure: GMNI offers the third option. We call it Managed Care. We would still rather you pick the arrangement that fits your organization.
How much does it cost to hire someone to manage a website?
We do not publish prices, and any single number would mislead you. The cost depends on:
- What the site does. A few pages of information is a different job from registrations, payments and a member area.
- How many plugins and integrations it runs. Each one is something to update, test and watch.
- How fast you need a response. Next business day and same hour are priced differently.
- Whether hosting is included.
- Whether improvements are included, or billed by the hour on top.
- The state of the site at handover. An out-of-date site needs catching up before routine care can start.
Ask each provider to quote against the same list, and compare what happens when something breaks, not just the monthly figure.
What should your organization own, whoever manages the site?
This part does not depend on who you hire.
- The domain, registered in the organization’s name with an organization email as the contact. For a .ca domain, CIRA’s WHOIS lookup shows the registrant for organizations, so you can check today.
- The hosting account, in the organization’s name, or a written agreement that you can move it.
- An administrator login that belongs to the organization, held by an officer and not shared.
- Backups you can get a copy of without asking permission.
- A one-page record: host, registrar, renewal dates, who has administrator access and who to call.
Responsibility stays with you, too. Under Ontario’s accessibility rules, the organization that controls the website, “either directly or through a contractual relationship”, is responsible for meeting the standard (ontario.ca). Hiring someone to manage the site does not hand the obligation to them. The AODA requires WCAG 2.0 AA on public websites for businesses and non-profits with 50 or more employees. We build to WCAG 2.2 AA regardless. See Does the AODA apply to your organization’s website?
A simple way to decide
Answer three questions in your next board or staff meeting.
- Who will edit the site? Name a person, and a backup.
- Who is answerable when it breaks at 9 p.m. the night before renewals close? If the honest answer is “whoever notices”, that is the gap to close.
- Who owns the accounts? If the answer is a person rather than the organization, fix that first, whatever else you decide.
If you would like to talk through which arrangement fits your organization, schedule a discussion.
Related: Managed Care · What a website care plan includes, and what it does not · Your volunteer webmaster is leaving: a handover checklist
Sources (checked 30 September 2026)
- WordPress Developer Resources, Hardening WordPress (updated 7 January 2026): https://developer.wordpress.org/advanced-administration/security/hardening/
- Canadian Centre for Cyber Security, Baseline cyber security controls for small and medium organizations (controls BC.2 patching, BC.7 backups, BC.12 administrative privileges): https://www.cyber.gc.ca/en/guidance/baseline-cyber-security-controls-small-and-medium-organizations
- Government of Ontario, How to make websites accessible (updated 21 September 2026): https://www.ontario.ca/page/how-make-websites-accessible
- CIRA, WHOIS domain name lookup: https://www.cira.ca/en/ca-domains/whois/
